Olympus DAO
DAMASCUSTreasury / Stablecoin · Ethereum · $200M+ TVL · 15 contracts
Public risk assessment — scores are produced with the same methodology as monitored protocols
Security Profile
82
55
75
68
70
80
97
78
72
89
82
55
75
68
70
80
97
78
72
89
Audit History
Bug Bounty Program
Assessment
BRI 720 within TEMPERED range. Pioneer reserve currency protocol that survived 90%+ drawdown. Economic model novel but proven fragile under stress (D2=55 is the primary drag). High maturity (Z=0.940, 60+ months) and no contract exploits. Maximum adversarial resilience (100) after 12/12 honest negatives. Strong access control (82) validated by graph analysis of 7 core contracts. Economic design remains the primary risk factor preventing DAMASCUS.
Dimension Breakdown
How scores work →- Kernel-Module architecture with permissioned modifier on all Module functions
- Kernel.modulePermissions cross-contract AC lookup gates every value-affecting function
- Emergency policy has 8 distinct bypass guards (all cost=1.0): onlyKernel, permissioned, onlyExecutor, onlyGovernor, onlyGuardian, onlyPermitted, onlyVault, onlyRole
- TRSRY authority_tau_star=0.75, MINTR/Staking/Clearinghouse/Emergency all tau_star=1.0
- Kernel.executeAction blast_radius=0.613 (highest) but onlyExecutor-gated
- Graph analysis: 7 contracts, 1633 functions, only 50 genuinely restricted at graph level (rest gated by cross-contract Kernel check)
- Novel reserve currency model (OHM backing)
- Experienced 90%+ drawdown from ATH (3,3 collapse)
- Range-bound stability (RBS) is V2 economic redesign
- Bond mechanism creates complex tokenomics
- Protocol-owned liquidity model proven but volatile
- Staking epoch.distribute == 0 means rebase is no-op currently
- Chainlink price feeds for treasury valuation
- Internal TWAP for Range-Bound Stability operations
- Moving average calculations for range walls
- Heart_v1_7 contract manages oracle heartbeat operations
- No oracle manipulation paths found in graph analysis
- Live since May 2021 (~60 months)
- No smart contract exploit despite high-profile target
- Survived extreme economic stress (90%+ OHM price decline)
- Multiple versions: V1, V2 (Bophades/Kernel), V3
- 105 deployed contracts analyzed -- extensive protocol surface
- Z-factor: 0.940
- Active DAO governance with proposal system
- Policy team (multisig) executes governance decisions
- GovernorBravoDelegate deployed for on-chain governance
- Kernel architecture provides governance flexibility
- Emergency contract properly gated with 8 guards for shutdown/restart
- Score derived from continuous adversarial security research
- Active team managing complex treasury operations
- RBS Heart requires operational monitoring
- Bond market operations need active management
- Experienced team that survived major stress events
- Emergency shutdown capability properly implemented
- OHM composed in various DeFi protocols
- Treasury holds diverse DeFi positions (LP tokens, etc.)
- Cooler Loans product composes OHM-DAI via Clearinghouse (697 nodes, 2052 edges)
- Cross-protocol treasury exposure
- Clearinghouse_v1_2 has 35 value state vars -- largest composition surface
- ConvertibleDepositFacility (1144 nodes) not deployed -- reduces active composition risk
- Appears in 2 cross-protocol cascade chain(s)
- Failure cascades to 2 downstream protocol(s)
- Member of 4 dependency cluster(s)
- Score: 89/100 (higher = more isolated from systemic risk)
- Source: cross_protocol_composition.json dependency analysis
- Standard Solidity dependencies (Solmate, OpenZeppelin)
- Custom Kernel/Module architecture (novel pattern)
- Compiler version v0.8.15+commit.e14f2714 (TRSRY), others vary
- Verified contracts on Etherscan
- No proxy patterns in core modules (is_proxy=false for all 7)
Risk Drivers
Primary risk factors driving this score, ordered by severity.
Adversarial Risk Signals
Observable security posture indicators. These signals reflect publicly verifiable information and responsible disclosure outcomes. No specific vulnerability details are exposed.
Score History & Verification
Score provenance tracking begins with the next reassessment.
On-Chain Data
- Protocol Slug
- "olympus"
- Oracle
- BRORegistry (Base)
- Evidence
- IPFS (pinned)
- Staleness Threshold
- 24 hours
registry.getScore("olympus")Reduce exploitable risk
BlackHart Monitoring provides continuous adversarial analysis, vulnerability detection, remediation support, and verified reassessment when your risk posture improves.